A cloud-based AI security system protects files and accounts with encryption, passwords, and access controls.
Microsoft has cancelled roadmap item 558436, "Microsoft Purview: Credential Scanning in Data Security Posture Agent." The entry was updated on October 5, 2026 to say Microsoft had decided "not to move forward with this change at this time," and its status is now Cancelled. The timing is awkward. The roadmap had promised a preview in March 2026 and general availability (GA) in October 2026, and October has just started.

The scope matters. This is a cancellation of one roadmap item. It doesn't mean Purview has dropped data security posture work in general, and it certainly doesn't make any passwords or tokens sitting in your SharePoint libraries any safer.

What Microsoft Had Promised​

The roadmap entry said Microsoft was adding a credential scanning capability to the Data Security Posture Agent in Microsoft Purview. Admins would give the agent scanning tasks for selected data locations. It would analyze the files in scope, look for credentials such as Microsoft Entra user credentials, private keys and API tokens, and show the results on one task board.

Each finding was supposed to include four things:

  • A risk score, so teams could fix the worst problems first
  • AI-generated insights explaining why the item was flagged
  • A confidence score showing how sure the model was
  • A credential category, so findings could be grouped by type

The listing named Microsoft Purview as the product, the web as the platform, Worldwide (Standard Multi-Tenant) as the cloud, and both Preview and General Availability as release rings.

The matching Message Center post, MC1259828, said the feature would use LLM-powered detection to identify exposed credentials like Entra ID credentials, private keys, and API tokens. In other words, it would use a large language model to understand what a document means, not just match text patterns. Microsoft's Security Copilot blog made the same pitch, saying the capability helps data security teams proactively identify exposed credentials within their data environment.

Section summary: The feature was meant to find exposed passwords, keys and tokens in your Microsoft 365 content and rank them for review. That plan is now cancelled.

The Schedule Slipped Before It Was Cancelled​

Message Center archives show the dates moving before the plan was dropped:

MilestoneOriginal plan (March 2026)Revised plan (June 2026)October 5, 2026
Public previewLate March to early April 2026UnchangedCancelled
General availabilityLate June to early July 2026Early October to early November 2026Cancelled

The first post, mirrored by M365 Admin, said GA (Worldwide) will begin in late June 2026 and complete by early July 2026. A later update, archived by MWPro, moved GA to early October 2026 (previously late June) and complete by early November 2026 (previously early July). MWPro's summary of the October 5 change says admins and security teams only need to be aware that the rollout will not proceed and pause related preparation or communication.

If you have been in IT for a while, you know this pattern: a launch slips once, and then the next notice cancels it. It's annoying, but it's better than shipping something half-finished to production tenants.

So What About the Preview Already Documented on Microsoft Learn?​

This part can confuse people. Microsoft Learn has a page called "Get started with the Data Security Posture agent (preview) in Data Security Investigations," last updated March 23, 2026. It describes a credential-scanning workflow that runs across Microsoft 365 locations (SharePoint, OneDrive, Exchange, Teams). That page shows Microsoft documented a preview of Posture agent scanning in Purview.

What it doesn't show is that roadmap item 558436 reached preview in exactly the promised form. It also doesn't say whether that documented preview will stay available now that the roadmap item is cancelled. Microsoft hasn't explained what happens to the preview. If your tenant already has it, check what is actually in your Purview portal. Don't assume it either stays or disappears.

For tenants where the preview is present, Learn documents this workflow:

Prerequisites

  • You must be in a role group that includes Posture agent access.
  • The agent must be enabled in the Purview portal.
  • Your organization needs Security Copilot Security Compute Units (SCUs) provisioned, because the agent runs on that capacity.
  • You don't have to set up Data Security Investigations itself. Its other features, such as creating investigations and AI analysis, still need separate configuration and billing.

Enable the agent

  1. Go to the Microsoft Purview portal and sign in by using the credentials for a user account assigned the appropriate permissions.
  2. Select Agents in the left navigation.
  3. Select Explore agents, and then select View details for the Posture agent in Data Security Investigations.
  4. Select Set up. If the agent is already enabled in Data Security Posture Management (DSPM), you don't need to do this again.

Create a scanning task

  1. Go to Data Security Investigations and select Posture agent.
  2. Select Assign to agent to create a credential scanning task.
  3. Name the task, then set the data sources. You can select a tenant-wide scan or narrow the scope to your organization, specific sites, users, mailboxes, or groups.
  4. Select Save. If you like, add plain-language guidance under Additional context for AI, then select Create.

What success looks like: The task shows up in the In progress column of a Kanban-style board. When scanning finishes it moves to Ready for review, and it goes to Closed after a reviewer marks it done. Reviewers can sort findings by High, Medium or Low risk, group them by credential category, read the AI's reasoning, download reports, and run Kusto Query Language (KQL) queries against the findings in Data Explorer.

Common problem: If a scan has the wrong scope, Learn says you can stop the task and create a new one with the correct scope.

Analysis: Why This Matters, and Why It Isn't a Crisis​

Credentials left in documents, emails and chats are a real problem. Old deployment notes with a service account password, an API token pasted into a Teams chat, a private key attached to an email from years ago: all of these build up quietly. Anyone who gets access to that content, including an AI assistant that can search it, may find them. An agent that ranked those findings by risk would save a lot of manual searching.

There are good reasons to stay cautious about any AI scanner like this, though. Microsoft's own Learn page warns that AI results may be inaccurate or incomplete and should be checked. One Purview practitioner blog put it simply: Don't treat credential findings as automatically true. Always validate with context, because AI outputs can be wrong or incomplete. A risk score helps you decide what to look at first. It doesn't prove a credential is valid, exposed to an attacker, or exploitable. The SCU requirement also means each scan uses paid capacity, so it isn't a free safety net.

There is one conflict in the coverage. At least one consulting firm's blog says the Posture Agent reached GA in late March 2026, while the Learn page still calls the Posture agent a preview. Treat Microsoft's own documentation and your tenant's admin center as the better guide.

What Admins Should Do Now​

  • Remove GA plans: Take the October 2026 GA estimate out of your rollout plans, change-advisory calendars and user communications.
  • Check your tenant: If you already use the documented preview, confirm what is in your portal before you build a process around it.
  • Keep existing secret hygiene: The cancellation doesn't change any controls you already rely on, such as sensitive information types, DLP policies or secret scanning in code repositories.
  • Assume secrets are still out there: Any credentials sitting in your Microsoft 365 content are still a risk. Plan how you'll find and rotate them with tools you have today.
  • Watch MC1259828: Microsoft said "at this time," which leaves the door open. Any return of the feature would probably be announced through Message Center.

Bottom line: A promised Purview feature is off the roadmap for now. The risk it was meant to address hasn't gone anywhere, so keep hunting for those exposed credentials with the tools you already have.

 

References

  1. Microsoft Purview: Credential Scanning in Data Security Posture Agent Microsoft 365 Roadmap 2026-10-05T23:03:05.040986Z
  2. Microsoft Purview Credential Scanning Update MC1259828 mwpro.co.uk
  3. Get started with the Data Security Posture agent (preview) in Data Security Investigations learn.microsoft.com